CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2014-6567

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.

    Published: 21 Jan 2015
    4.9
    Medium

    CVE-2014-6570

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6600 and CVE-2015-0397.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-6577

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the original researcher's claim that this is an XML external entity (XXE) vulnerability in the XML parser, which allows attackers to conduct internal port scanning, perform SSRF attacks, or cause a denial of service via a crafted (1) http: or (2) ftp: URI.

    Published: 21 Jan 2015
    6.5
    Medium

    CVE-2014-6578

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Workspace Manager component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SDO_TOPO and WMSYS.LT.

    Published: 21 Jan 2015
    5.5
    Medium

    CVE-2014-6586

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Time and Labor.

    Published: 21 Jan 2015
    3.2
    Low

    CVE-2014-6588

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6589, CVE-2014-6590, CVE-2014-6595, and CVE-2015-0427.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-6594

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Learner Pages.

    Published: 21 Jan 2015
    3.2
    Low

    CVE-2014-6595

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6590, and CVE-2015-0427.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-1204

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php.

    Published: 21 Jan 2015
    6.3
    Medium

    CVE-2014-6541

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality via vectors related to DBMS_IR.

    Published: 21 Jan 2015
    4.6
    Medium

    CVE-2014-6548

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 allows local users to affect confidentiality, integrity, and availability via vectors related to B2B Engine.

    Published: 21 Jan 2015
    4.6
    Medium

    CVE-2014-6556

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2014-6566

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via unknown vectors related to Portal.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-6565

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-6571

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2011-1944.

    Published: 21 Jan 2015
    6.4
    Medium

    CVE-2014-6572

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-6573

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 11.1.3 and 12.1.4 allows remote attackers to affect integrity via unknown vectors related to User Interface Framework.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-6575

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230.

    Published: 21 Jan 2015
    6.4
    Medium

    CVE-2014-6581

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Extract/Load Programs.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-6582

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Rapid Implementation.

    Published: 21 Jan 2015
    6.4
    Medium

    CVE-2014-6583

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3. allows remote attackers to affect confidentiality and integrity via unknown vectors related to Audience.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2014-6584

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite ILOM before 3.2.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Backup Restore.

    Published: 21 Jan 2015
    3.2
    Low

    CVE-2014-6590

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6595, and CVE-2015-0427.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-6596

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0553

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-1032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-1028

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy Configuration Panel); the (2) brName parameter to lancfg2get.cgi (Lan Configuration Panel); the (3) wlAuthMode, (4) wl_wsc_reg, or (5) wl_wsc_mode parameter to wlsecrefresh.wl (Wireless Security Panel); or the (6) wlWpaPsk parameter to wlsecurity.wl (Wireless Password Viewer).

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-1164

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

    Published: 21 Jan 2015
    9
    Critical

    CVE-2014-3440

    Last Modified: 12 Apr 2025

    The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-9224

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-9597

    Last Modified: 12 Apr 2025

    The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-0513

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged access to set crafted values of unspecified fields.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-6172

    Last Modified: 12 Apr 2025

    IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors.

    Published: 21 Jan 2015
    6.5
    Medium

    CVE-2014-7289

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-8913

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8914.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-8914

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8913.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2014-9225

    Last Modified: 12 Apr 2025

    The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.

    Published: 21 Jan 2015
    7.2
    High

    CVE-2014-9226

    Last Modified: 12 Apr 2025

    The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-9598

    Last Modified: 12 Apr 2025

    The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2015-0514

    Last Modified: 12 Apr 2025

    EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.

    Published: 21 Jan 2015
    6.5
    Medium

    CVE-2015-0515

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0516

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2015-0867

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.

    Published: 21 Jan 2015
    7.2
    High

    CVE-2014-6524

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-6525

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Templates.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-6526

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 allows remote attackers to affect integrity via unknown vectors related to Admin Console.

    Published: 21 Jan 2015
    9
    Critical

    CVE-2014-4259

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to System management.

    Published: 21 Jan 2015
    7.2
    High

    CVE-2014-6510

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-4279

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-6481

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL.

    Published: 21 Jan 2015